Privacy Policy
This document is the text published at peonix.app/privacy — it is rendered from this file, so what an attorney reviews is exactly what the site serves. It was prepared by the operator with AI assistance and is not legal advice; it is scheduled for review by licensed counsel before scale. Questions: support@peonix.app
Last updated: August 1, 2026
Who we are. Peonix (the "Platform") is operated by Greenwind LLC, a Florida limited liability company with its registered office in St. Petersburg, Pinellas County, Florida ("we," "us," "our"). This Privacy Policy explains what personal information we collect and how we use it.
Two kinds of users. We serve (1) merchants — flower shops that use the Platform to run their business — and (2) storefront customers — people who place orders through a merchant's public online store. For storefront customer information, the merchant is responsible for how that information is used; we process it on the merchant's behalf. If you are a storefront customer with questions about your data, please contact the shop you ordered from; you may also contact us at the address below.
Contact: support@peonix.app · Greenwind LLC, St. Petersburg, Florida, USA. A postal address is available on request and is included in our commercial email as required by law.
Information we collect
From merchants (when you sign up and use the Platform):
- Account details: name, email address, password (stored hashed), and staff you invite.
- Business information: shop name, contact details, delivery zones, tax settings, and storefront configuration.
- Usage and device data: log records, session cookies, and basic technical information.
- Billing information is collected and processed by our payment processor when paid plans are enabled; we do not store full card numbers.
From storefront customers (when you order through a shop's online store):
- Contact and delivery details: name, phone number, delivery address, and (optionally) email.
- Order details: items ordered, recipient information, gift messages, delivery date and instructions.
Automatically:
- A strictly necessary session cookie to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising cookies.
How we use information
- To provide and operate the Platform and the merchant's store.
- To process and fulfill orders and send transactional notifications (for example, order updates) on the merchant's behalf.
- To secure the Platform, prevent abuse, troubleshoot, and keep audit records.
- To communicate with merchants about their account and the service.
- To comply with legal obligations.
We do not sell personal information, and we do not use storefront customers' data for our own marketing.
How we share information
We share information only with service providers that help us run the Platform, each limited to what it needs:
- Hosting — Vultr (Constant Company, LLC). The application, its database and the photos merchants upload all live on a server in Miami, Florida, United States, and so do the backups.
- Email provider (Resend) to deliver transactional email.
- Telegram, only where a merchant enables Telegram notifications.
- Website analytics (Umami) on our public marketing pages only: aggregate page counts, no cookies, no cross-site tracking, no advertising identifiers. The Platform itself carries no analytics.
- Payment processor (Stripe) for subscription billing — we never see full card numbers.
- AI provider (Anthropic, model Claude Haiku 4.5), only where a merchant's administrator has switched on the assistant's answers in words — and only for shops on a plan that includes it. Nothing is sent unless that switch is on: without it the assistant answers from our own server and reaches no third party at all. When it is on, what leaves is the question the person typed and the rows of the answer our server has already computed — figures, flower and bouquet names, and the prices and stock levels of the shop's materials. Customer names are replaced with «Customer #3» except in a question about one named customer, where the name is the question. Order notes, gift-card messages, addresses, phone numbers, email addresses, payment details and passwords are never sent. Anthropic does not train its models on this data and retains it for 7 days. The merchant's consent is recorded with the name of the person who gave it, the date, and the revision of the disclosure they read; a materially changed disclosure pauses the feature until it is agreed again.
We may also disclose information if required by law or to protect our rights, and in connection with a business transfer (e.g., merger or sale), subject to this Policy.
Where your data is stored
In the United States. The Platform runs on a single server in Miami, Florida, and its backups are held in the same facility. We do not currently copy data to any other country or to any other storage provider; if that changes, this Policy and the list above change with it before the data moves.
Data storage, security & retention
Data is stored in a PostgreSQL database with per-shop isolation so shops cannot access one another's data. We use signed session cookies, restrict access to production data, keep platform secrets out of the database, and apply security controls appropriate to the service. No method of storage or transmission is 100% secure.
We keep information for as long as an account is active and as needed to provide the service, then delete or anonymize it within a reasonable period (target 30 days after account closure), except where longer retention is required by law. One shorter window is worth naming on its own: where a shop has switched on the assistant's answers in words, we keep the text of each question for 90 days — so we can see what the assistant is failing to understand — after which the text is deleted and only the numbers (which function ran, how long it took, what it cost) remain. Backups cycle out on a rolling basis: we keep 7 daily and 4 weekly copies, so a restore can reach back about 28 days. A deletion therefore also clears from backups within that window.
Your choices and rights
- Merchants can access and update account information in Settings, request an export of their shop's data, and request deletion of their account.
- Storefront customers should direct requests about their order data to the shop they ordered from (the controller). You may also contact us and we will route your request to the relevant shop.
- Depending on where you live, you may have rights to access, correct, or delete your personal information. To make a request, email support@peonix.app; we respond within 30 days.
- California residents. We do not sell or share personal information as the CCPA/CPRA define those terms, and we do not use it for cross-context behavioural advertising. We honour access, correction, deletion and portability requests, and we will not discriminate against you for making one.
- EEA / UK visitors. Where the GDPR applies, we process merchant account data to perform our contract with you and on our legitimate interest in running and securing the service; storefront customer data is processed on the merchant's instructions. You also have the rights to restriction, objection and portability, and the right to complain to your supervisory authority.
Children
The Platform is for businesses and is not directed to children under 13, and we do not knowingly collect their information.
Changes
We may update this Policy; we will post the new version with a revised effective date.
Governing law
This Policy is governed by the laws of the State of Florida, USA, without regard to conflict-of-laws rules.
Open items for counsel review: publish a postal address once a business mailing address is settled; a formal data-processing addendum (DPA) and subprocessor list once EU merchants sign up; confirmation of the retention windows against the backup schedule.